| 
 | 1 | +<<<<<<< HEAD  | 
 | 2 | +=======  | 
 | 3 | +Changes from version 0.28.2 to 0.28.3  | 
 | 4 | +-------------------------------------  | 
 | 5 | + | 
 | 6 | +Release Notes:  | 
 | 7 | + | 
 | 8 | +* https://github.com/Exiv2/exiv2/issues/3008  | 
 | 9 | +* https://github.com/Exiv2/exiv2/milestone/14?closed=1  | 
 | 10 | + | 
 | 11 | +This release also fixes a low-severity security issue in asfvideo.cpp:  | 
 | 12 | + | 
 | 13 | +* [CVE-2024-39695](https://github.com/Exiv2/exiv2/security/advisories/GHSA-38rv-8x93-pvrh): out-of-bounds read in AsfVideo::streamProperties.  | 
 | 14 | + | 
 | 15 | +This vulnerability is in a new feature (ASF video) that was added in version 0.28.0, so earlier versions of Exiv2 are not affected.  | 
 | 16 | + | 
 | 17 | +Changes from version 0.28.1 to 0.28.2  | 
 | 18 | +-------------------------------------  | 
 | 19 | + | 
 | 20 | +Release Notes:  | 
 | 21 | + | 
 | 22 | +* https://github.com/Exiv2/exiv2/issues/2914  | 
 | 23 | +* https://github.com/Exiv2/exiv2/milestone/13?closed=1  | 
 | 24 | + | 
 | 25 | +This release also fixes two low-severity security issues in quicktimevideo.cpp:  | 
 | 26 | + | 
 | 27 | +* [CVE-2024-24826](https://github.com/Exiv2/exiv2/security/advisories/GHSA-g9xm-7538-mq8w): out-of-bounds read in QuickTimeVideo::NikonTagsDecoder.  | 
 | 28 | +* [CVE-2024-25112](https://github.com/Exiv2/exiv2/security/advisories/GHSA-crmj-qh74-2r36): denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder.  | 
 | 29 | + | 
 | 30 | +These vulnerabilities are in a new feature (quicktime video) that was added in version 0.28.0, so earlier versions of Exiv2 are not affected.  | 
 | 31 | + | 
 | 32 | +Changes from version 0.28.0 to 0.28.1  | 
 | 33 | +-------------------------------------  | 
 | 34 | + | 
 | 35 | +Release Notes:  | 
 | 36 | +https://github.com/Exiv2/exiv2/issues/2813  | 
 | 37 | + | 
 | 38 | +This release also fixes [CVE-2023-44398](https://github.com/Exiv2/exiv2/security/advisories/GHSA-hrw9-ggg3-3r4r), an out-of-bounds write in `BmffImage::brotliUncompress`. The vulnerability is in new code that was added in version 0.28.0, so earlier versions of Exiv2 are not affected.  | 
 | 39 | + | 
 | 40 | +Changes from version 0.27.6 to 0.28.0  | 
 | 41 | +-------------------------------------  | 
 | 42 | + | 
 | 43 | +Release Notes:  | 
 | 44 | +https://github.com/Exiv2/exiv2/issues/2406#issuecomment-1529139799  | 
 | 45 | + | 
 | 46 | +Changes from version 0.27.5 to 0.27.6  | 
 | 47 | +-------------------------------------  | 
 | 48 | + | 
 | 49 | +Closed:  | 
 | 50 | +https://github.com/Exiv2/exiv2/milestone/10?closed=1  | 
 | 51 | + | 
 | 52 | +Open:  | 
 | 53 | +https://github.com/Exiv2/exiv2/milestone/10?open=1  | 
 | 54 | + | 
 | 55 | +Release Notes:  | 
 | 56 | +https://github.com/Exiv2/exiv2/issues/2406#issuecomment-1383302378  | 
 | 57 | + | 
 | 58 | +Changes from version 0.27.4 to 0.27.5  | 
 | 59 | +-------------------------------------  | 
 | 60 | + | 
 | 61 | +Closed:  | 
 | 62 | +https://github.com/Exiv2/exiv2/milestone/9?closed=1  | 
 | 63 | + | 
 | 64 | +Open:  | 
 | 65 | +https://github.com/Exiv2/exiv2/milestone/9?open=1  | 
 | 66 | + | 
 | 67 | +Release Notes:  | 
 | 68 | +https://github.com/Exiv2/exiv2/issues/1018#issuecomment-948573657  | 
 | 69 | + | 
 | 70 | ++++++++++++++++++++++++++++++++++++++  | 
 | 71 | +------------- History ---------------  | 
 | 72 | ++++++++++++++++++++++++++++++++++++++  | 
 | 73 | + | 
 | 74 | +>>>>>>> c5b922cf5 (Exiv2 v0.28.3)  | 
1 | 75 | Changes from version 0.27.3 to 0.27.4  | 
2 | 76 | -------------------------------------  | 
3 | 77 | 
 
  | 
 | 
0 commit comments